Select Few Users Being Logged Out Constantly

Discussion in 'Troubleshooting and Problems' started by Zachary Ball, Mar 16, 2016.

  1. Zachary Ball

    Zachary Ball Member

    I need some assistance since i have exhausted all efforts here :(

    I have, to my attention about 5-10 users who are constantly being logged out. There is a login box that will pop up which i have never seen on my end.

    Now, I have spent countless hours reading all of the threads here that report it being a problem with cache, www or non www inconsistency and settings within the APC.

    I have checked everything and still can't figure this out. I have timeout set at 60 which is max. Someone maybe shed some light? These users can't complete 1-2 tasks without being asked to log back in.
  2. Brogan

    Brogan XenForo Moderator Staff Member

    The 60 minute setting in the ACP is just related to who shows as being online, it isn't related to session timeout, which is always 60 minutes.

    However, any request will extend it, including requests such as draft saving, and if the window is focussed, a request will always be made that keeps the session alive.

    Are they checking "Stay logged in" when they log in?

    Is their IP address changing? If it is, the existing session won't be used but selecting the option to stay logged in adds a cookie which automatically recreates the session as needed.

    It may be worth asking one of them for permission to log in to their account to see if you can reproduce it.
  3. Zachary Ball

    Zachary Ball Member

    Hey Brogan,

    The "stay logged in" button is selected by default on my website. I have checked thier account and only see one IP address unless that one continuously changes.

    Anything else?
  4. Digital Doctor

    Digital Doctor Well-Known Member

    Ask them to try different computers and or different browsers.
  5. Zachary Ball

    Zachary Ball Member

    I have done this, did not work on Chrome or Mozilla for them. I don't think they will have a chance to try a different computer.
  6. Brogan

    Brogan XenForo Moderator Staff Member

    If it's only affecting a few users then it's likely going to be an issue local to them.

  7. Zachary Ball

    Zachary Ball Member


    I now am getting users every 30 minutes to an hour having this issue. This is happening to pretty much everyone now and I am trying to figure out why.
  8. Digital Doctor

    Digital Doctor Well-Known Member

  9. Zachary Ball

    Zachary Ball Member

    Already have been to those links and tried just about everything you have here. I was able to fix the issue by increasing memcached but it is acting up again today. Pretty much every action I or my users do, it logs us out and pops up a login box to yet again log in...

  10. Daniel Hood

    Daniel Hood Well-Known Member

    So, that pretty much confirms what the issue is. Your memcache is likely full again. So your options are to restart it and clear it out or increase the limit again. Increasing the limit every time you reach the limit is obviously a temporary fix.
  11. Zachary Ball

    Zachary Ball Member

    That doesn't make sense.. It should not be filling or ever reaching full capacity. Literally just cleared it the other day so I think there is a deeper issue.
  12. Zachary Ball

    Zachary Ball Member

    I have a few pages that aren't being displayed as secured and those seem to be the clicks that trigger the log out. My redirect for all pages to be secure is not working like it should. That is the problem, any fixes?
  13. Daniel Hood

    Daniel Hood Well-Known Member

    Yes, that would definitely cause it.

    What kind of redirect are you doing? With out knowing your particular set up it's hard to give advice. Really the bigger problem is that they're linked to the insecure version at all, the redirect is handy if they try going to it manually but all of your internal links should be standardised so this shouldn't be that common of a problem.
  14. Zachary Ball

    Zachary Ball Member

    #RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

    I believe.. Also we are hosting the website on our own server.

